The vulnerabilities exist in various features inside the operating system, including AppArmor and QuickConnect. An attacker could exploit both vulnerabilities to steal sensitive login credentials, including those of an administrator. Users are encouraged to update these affected products as soon as possible: Synology DSM, version 6.2.3 25426-2 DS120j. The following SNORT (SNORT) rules will detect exploitation attempts against this vulnerability: 55917 and 56137. An update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure policy.”]
Source: https://blog.talosintelligence.com/2021/04/vuln-spotlight-synology-dsm.html

